Management is considering hiring employees that will work remotely. What's your advice for devising a remote access security policy for a small company?

The ideal remote access policy will keep data secure without interfering with employees' ability to do work. Without knowing much about this particular situation, I'll assume that an SSL VPN will fit your needs, though an IPsec VPN will also work.

By submitting your personal information, you agree to receive emails regarding relevant products and special offers from TechTarget and its partners. You also agree that your personal information may be transferred and processed in the United States, and that you have read and agree to the Terms of Use and the Privacy Policy.

Practically speaking, there are a few considerations to keep in mind: Authentication methods, access control, deciding which systems or applications the employees need to access remotely and what types of devices they are permitted to use.

Some sort of strong authentication should be used, such as tokens, smart cards or out-of-band SMS messages. Of the above, SMS messages will probably be the easiest piece to figure out.

When it comes to access control, be prepared for scope creep if the project doesn't already include full network access for all employees; once word gets out that this system is available, everyone will want to use it and everyone will want to be able to access all the internal systems. To handle this, be sure to scope the physical gateway devices to handle a larger load then initially projected.

The toughest question will concern which devices can remotely access the network. Users will want to use their personal computers, cell phones, even Internet kiosks. This is something to discuss with company management in order to come up with a policy they approve of and are willing to enforce. While there is technology to limit users to specific devices, it is important to communicate the company's policies to users and what the consequences are for breaking the rules.

0 comments

E-Mail

Username / Password

Password

By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy